Review cadence explained
How to plan recurring security reviews
Review cadence is how often you commit to checking controls, policies or providers. A review against one date differs from showing operation throughout a period.
Use your commitment
Set intervals to match your own policy and applicable obligations. If the policy promises quarterly reviews, an annual default does not satisfy that promise.
Choose the review perspective
Rolling review asks whether something is current now. Point-in-time review asks whether it was valid as of a specified date. Period-of-time review asks whether it operated throughout a window and needs supporting history.
Record the real review
Verify evidence before marking a control reviewed. Generating or approving a document does not by itself renew a control’s evidence. Check the Cadence screen for due work and for any warning that reminders are not configured.